<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:zeroclaw:zeroclaw:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3azeroclawzeroclaw/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 20:36:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3azeroclawzeroclaw/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in ZeroClaw Plugin Installation</title><link>https://feed.craftedsignal.io/briefs/2026-09-zeroclaw-path-traversal/</link><pubDate>Wed, 30 Sep 2026 20:36:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-zeroclaw-path-traversal/</guid><description>ZeroClaw versions before 0.8.5 are vulnerable to path traversal via the plugins-wasm feature, allowing attackers to overwrite arbitrary files through crafted plugin manifest files.</description><content:encoded><![CDATA[<p>ZeroClaw versions prior to 0.8.5 are susceptible to a path traversal vulnerability when the plugins-wasm feature is enabled. The vulnerability stems from insufficient input validation of the wasm_path field within the plugin manifest file during installation. An attacker can create a malicious plugin containing a crafted manifest file that specifies arbitrary filesystem locations for the plugin component. When a user installs the malicious plugin, the application fails to sanitize this path, resulting in the plugin writing or overwriting files outside the intended plugins directory. This behavior can be leveraged to overwrite sensitive system files or shell configuration scripts, potentially leading to remote code execution under the context of the user running the ZeroClaw application. This issue impacts all platforms where ZeroClaw is deployed if the vulnerable plugins-wasm feature is active.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthorized file writes on the host system. By targeting shell startup files or other sensitive configuration locations, an attacker can achieve code execution, potentially leading to full system compromise or persistence. This vulnerability poses a high risk to environments where users frequently install third-party plugins from untrusted sources.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade ZeroClaw to version 0.8.5 or later to patch CVE-2026-101885.</li>
<li>Disable the plugins-wasm feature if it is not required for operational workflows until the environment can be updated.</li>
<li>Implement file integrity monitoring on critical configuration directories and shell startup scripts to detect unauthorized file modifications associated with plugin installation events.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>path-traversal</category><category>remote-code-execution</category></item></channel></rss>